)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"8d609f566f7634f3d321ba6f1c61b3caf979c0c2","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"8b315333_5907e167","updated":"2026-07-14 16:22:57.000000000","message":"IMHO users should configure their reverse proxy appropriately not to pass down the request header from client. The proposed logic doesn\u0027t allow us to mitigate the risk fully. Note that the feature is optional, so we expect users should understand how the header will be used and how it should be set in the upper reverse proxy.","commit_id":"6c2298ba91636f7e87dd21209d4d63731757baeb"}]}
